{ "schema_version": "1.4.0", "id": "GHSA-c4c3-j73v-634r", "modified": "2024-05-27T20:31:59Z", "published": "2024-05-27T20:31:59Z", "aliases": [], "summary": "silverstripe/framework has Cross-site Scripting vulnerability in page history comparison", "details": "Authenticated user with page edit permission can craft HTML, which when rendered in a page history comparison can execute client scripts.", "severity": [], "affected": [ { "package": { "ecosystem": "Packagist", "name": "silverstripe/framework" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "3.4.0-rc1" }, { "fixed": "3.4.6" } ] } ] }, { "package": { "ecosystem": "Packagist", "name": "silverstripe/framework" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "3.5.0-rc1" }, { "fixed": "3.5.4" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/silverstripe/silverstripe-framework/commit/2b72c0f73b668ddf7c059319da915a6c08652278" }, { "type": "WEB", "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-004-1.yaml" }, { "type": "PACKAGE", "url": "https://github.com/silverstripe/silverstripe-framework" }, { "type": "WEB", "url": "https://www.silverstripe.org/download/security-releases/ss-2017-004" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-27T20:31:59Z", "nvd_published_at": null } }